Environment
Question
Why does the Alert severity in the console not match the severity for the same Alerts sent to the SIEM?
Answer
- The Alert severity in the console can change as new events are added to it
- If the Alert severity changes the new severity will not be sent to the SIEM
Additional Notes
- This is currently as designed. To request this behavior changed a feature request can be submitted
- This behavior will also prevent any new events added to the alert from being sent after the SIEM pulls the related events the first time
- This is for when using notifications to push alerts/events to a SIEM
Related Content